SY0-701 exam dumps

SY0-701 practice question 51 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 51

Single answer2.1 Compare and contrast common threat actors and motivations.

A regional power utility discovers that several engineering workstations in its operational technology (OT) environment were infected with custom malware designed to remain undetected for months. Investigators determine the malware collected network diagrams, remote access configurations, and details about programmable logic controllers (PLCs), but it did not attempt to steal customer payment data or deploy ransomware. The utility's leadership is most concerned that the activity was intended to support future disruption of critical infrastructure during a period of geopolitical tension. Which threat actor is the MOST likely responsible?

  1. A

    An organized crime group seeking financial gain

  2. B

    A nation-state actor conducting reconnaissance for strategic objectives

  3. C

    A script kiddie experimenting with publicly available tools

  4. D

    An insider motivated primarily by personal revenge

Show answer and explanation

Correct answer: B

Explanation

The best answer is a nation-state actor because the scenario emphasizes critical infrastructure targeting, stealthy persistence, OT-specific reconnaissance, and a strategic non-financial objective. In Security+ threat-actor analysis, motivation is a key differentiator: organized crime usually seeks money, insiders often act from revenge or personal benefit, and script kiddies typically lack advanced capability and strategic intent. Nation-state actors, by contrast, commonly conduct long-term espionage and pre-attack reconnaissance against sectors such as energy, water, transportation, and telecommunications. This aligns with guidance from CISA and NIST, which both emphasize that advanced persistent threats and state-sponsored actors often target industrial control systems and critical infrastructure to support national objectives rather than immediate profit.

  • A. Incorrect.

    Incorrect. Organized crime groups are typically motivated by financial gain, such as ransomware, fraud, extortion, or theft of monetizable data. In this scenario, the attacker focused on long-term stealth, OT intelligence collection, and infrastructure mapping rather than immediate profit. Those indicators do not align well with the usual criminal objective of direct monetary return.

  • B. Correct.

    Correct. Nation-state actors commonly target critical infrastructure, especially utilities, for espionage, pre-positioning, and potential future disruption in support of geopolitical or military objectives. The use of custom malware, prolonged dwell time, focus on PLC and remote access information, and lack of obvious financial motive strongly indicate a state-sponsored campaign centered on strategic reconnaissance.

  • C. Incorrect.

    Incorrect. Script kiddies generally rely on readily available tools and usually lack the capability, patience, and operational discipline needed to develop or deploy custom malware that persists in OT networks for months. Their motivation is more often curiosity, notoriety, or opportunistic disruption rather than strategic intelligence collection against critical infrastructure.

  • D. Incorrect.

    Incorrect. An insider acting out of revenge could potentially target systems for sabotage, but this scenario points to a sophisticated external operation: custom malware, extended covert collection, and targeted reconnaissance of industrial control components. The evidence is more consistent with a well-resourced actor pursuing broader strategic goals than with a disgruntled employee focused on personal retaliation.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam